CVE-2025-67806 describes a username enumeration vulnerability in Sage DPW versions prior to 2021_06_000, where the login mechanism provides distinct responses for valid and invalid usernames. This allows an unauthenticated network attacker to identify existing user accounts. The vulnerability has a CVSS score of 3.7 (LOW) due to its high attack complexity and limited impact on confidentiality. There is currently no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this issue are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2025_06_004CPE matchmatch criteria | cpe:2.3:a:sagedpw:sage_dpw:2025_06_004:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.